Information Security and GRC Manager
Quick Summary
Run our SOC 2 program end to end. This covers control ownership, evidence collection, auditor management, and closing gaps,
Howdy, I'm JJ, Scribe's Head of Legal! I spend my days making sure the promises Scribe makes to customers are ones we can keep, and I'm looking for the person who makes sure our security team keeps them too. We take the work seriously but not ourselves, and I think the best colleagues still have time for hobbies and families (and the occasional unread Slack!).
I'm invested in making sure you grow your expertise and your career with the function the whole way. Come do the best work of your career with me!
Scribe is where exceptional people come to do the best work of their careers. More than 94% of the Fortune 500 use Scribe to own their specialized intelligence: the unique way their teams work, decide, and get things done. Our Specialized Intelligence platform automatically captures how work happens and turns it into a living asset for people and AI agents.
We're growing fast. Since our founding in 2019, we've reached 7 million users across 600,000 businesses. Based in San Francisco, we're a LinkedIn Top Startup, valued at over $1B, and backed by leading investors. Join us in our mission to transform how people work.
About the Role
~1 min read6+ years of experience in information security, GRC, or security compliance at a SaaS or technology company with 2+ years managing individual contributors.
Hands-on experience running SOC 2 Type II audits, as the person who actually did the work rather than an occasional contributor.
Experience handling enterprise customer security reviews and questionnaires alongside Sales, Customer Success, and Legal.
Enough working knowledge of cloud security, identity and access management, endpoint security, and vulnerability management to engage credibly with engineers and push remediation forward.
Familiarity with GRC automation platforms (e.g., Vanta, Drata, Secureframe).
Sound judgment about risk: you can tell what needs immediate attention from what can wait, and you escalate the right things.
Strong organization and follow-through, and comfort working without a large team around you.
Experience with information security and privacy frameworks like ISO 27001, HIPAA, FERPA, public-sector requirements, and AI governance frameworks (e.g., EU AI Act, ISO 42001).
CISSP, CISM, or CISA certification preferred.
If you're reading this thinking "that's me!", we want to meet you!
You don't have experience scaling or executing on a security team at a global SaaS or technology company.
You haven't personally engaged in commercial/GTM negotiations and other processes, or run audits, answered security questionnaires, or driven remediation work.
You treat every finding as requiring maximum mitigation regardless of business context.
You need a fully defined playbook. The program is still maturing, and you'll help build the processes you run.
Responsibilities
~1 min readSalary and office requirements vary by location. All full-time employees receive equity in Scribe. Final offers depend on experience and scope.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- October 9, 2026
- First seen
- October 9, 2026
- Last seen
- October 10, 2026
Posting Health
- Days active
- 1
- Repost count
- 0
- Trust Level
- 60%
- Scored at
- October 11, 2026
Signal breakdown
4 other jobs at
View all →Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.